PHP Remote File Inclusion Vulnerability in DFDevelopment Ronneby Theme Core
CVE-2025-63036

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2025-63036?

The DFDevelopment Ronneby Theme Core contains a vulnerability that allows for PHP Local File Inclusion due to improper control of the filename for include or require statements. This flaw can expose sensitive files on the server and can be exploited by attackers to execute arbitrary code or access confidential information. The affected versions of the Ronneby Theme Core extend from not applicable up to and including version 1.5.68, making it imperative for users to update their installations to mitigate potential risks.

Affected Version(s)

Ronneby Theme Core <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.
CVE-2025-63036 : PHP Remote File Inclusion Vulnerability in DFDevelopment Ronneby Theme Core